CVE-2025-15052: code-projects Student Information System profile.php cross site scripting
A vulnerability was detected in code-projects Student Information System 1.0. This vulnerability affects unknown code of the file /profile.php. Performing manipulation of the argument firstname/lastname results in cross site scripting. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15052?
CVE-2025-15052 is classified as a cross-site scripting vulnerability, which poses a moderate risk to users of the affected system.
How do I fix CVE-2025-15052?
To fix CVE-2025-15052, ensure proper input sanitization and validation for the firstname and lastname parameters in the /profile.php file.
Who is affected by CVE-2025-15052?
CVE-2025-15052 affects users and administrators of the code-projects Student Information System 1.0 software.
What type of vulnerability is CVE-2025-15052?
CVE-2025-15052 is a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts.
Can CVE-2025-15052 be exploited remotely?
Yes, CVE-2025-15052 can be remotely exploited by manipulating the argument firstname/lastname in the URL.